High - CVE-2024-8979 - The Essential Addons for Elementor – Best...
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
NA - CVE-2021-3740 - A Session Fixation vulnerability exists in...
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password,...
NA - CVE-2021-3741 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG file containing a...
NA - CVE-2021-3742 - A Server-Side Request Forgery (SSRF)...
A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allows an attacker to upload an SVG file containing...
NA - CVE-2021-3838 - DomPDF before version 2.0.0 is vulnerable to...
DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files...
NA - CVE-2021-3841 - sylius/sylius versions prior to 1.9.10,...
sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts...
NA - CVE-2021-3902 - An improper restriction of external entities...
An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all...
NA - CVE-2021-3986 - A vulnerability in janeczku/calibre-web allows...
A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name...
NA - CVE-2021-3987 - An improper access control vulnerability exists...
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the...
NA - CVE-2021-3988 - A Cross-site Scripting (XSS) vulnerability...
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when editing book properties, such as uploading a cover...